Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-08-29 CVE-2022-36553 Command Injection vulnerability in Hytec Hwl-2511-Ss Firmware 1.05
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.
network
low complexity
hytec CWE-77
critical
9.8
2022-08-29 CVE-2022-36554 Command Injection vulnerability in Hytec Hwl-2511-Ss Firmware 1.05
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.
network
low complexity
hytec CWE-77
critical
9.8
2022-08-29 CVE-2022-36556 Command Injection vulnerability in Seiko-Sol products
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.
network
low complexity
seiko-sol CWE-77
critical
9.8
2022-08-29 CVE-2022-36559 Command Injection vulnerability in Seiko-Sol Skybridge Mb-A200 Firmware 01.00.04
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.
network
low complexity
seiko-sol CWE-77
critical
9.8
2022-08-15 CVE-2022-36523 Command Injection vulnerability in Dlink Go-Rt-Ac750 Firmware 101B03/200B02
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
network
low complexity
dlink CWE-77
critical
9.8
2022-08-10 CVE-2022-34660 Command Injection vulnerability in Siemens Teamcenter
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2).
network
low complexity
siemens CWE-77
critical
9.8
2022-08-03 CVE-2022-34974 Command Injection vulnerability in Dlink Dir820La1 Firmware 102B22
D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.
network
low complexity
dlink CWE-77
critical
9.8
2022-08-02 CVE-2020-28423 Command Injection vulnerability in Monorepo-Build Project Monorepo-Build
This affects all versions of package monorepo-build.
network
low complexity
monorepo-build-project CWE-77
critical
9.8
2022-08-02 CVE-2020-28425 Command Injection vulnerability in Curljs Project Curljs
This affects all versions of package curljs.
network
low complexity
curljs-project CWE-77
critical
9.8
2022-08-02 CVE-2020-28433 Command Injection vulnerability in Node-Latex-Pdf Project Node-Latex-Pdf
This affects all versions of package node-latex-pdf.
network
low complexity
node-latex-pdf-project CWE-77
critical
9.8